SlideShare une entreprise Scribd logo
1  sur  31
Business Continuity Management
Presenter



Jeremy Kaye, VP GRC Strategy
+44 20 7903 5139
jeremy.kaye@easy2comply.com




     Confidential
Housekeeping



• The slides for this event will be distributed
  afterwards
• The webinar recording will be archived on
  easy2comply website
• Answer all the polls
• Q & A at the end




                       Confidential
Dedication

We dedicate this webinar
to all those that lost their
      life in the Japan
 earthquake, those that
were injured, and to those
        that survived

Our thoughts and wishes
 are with the Japanese
        people
                          Confidential
What is easy2comply?

 easy2comply is a functionally-rich software
solution, that enable companies to effectively
 manage multiple GRC processes on a single
                   platform




                    Confidential
Webinar Focus



•   Continuity Statistics
•   Learning From Japan
•   Methodologies
•   Easy2comply New Techniques




                     Confidential
Statistics….

• 43% of companies experiencing disasters never re-open,
  and 29% close within two years (McGladrey and Pullen)
• A company that experiences a computer outage lasting
  more than 10 days will never fully recover financially (DRP
  – Jon Toigo)
• 88% of e-commerce is not
  covered by a DR / BC plan (HP)
• 42% of managers do not believe
  their plans would be effective
  (HP)


                            Confidential
….and more statistics

  • 50% of UK businesses do not
    have a BC plan
  • 79% of those that had plans and
    were forced to use them found
    a significant reduction in the
    impact
  • Fewer than half that had plans
    actually tested them
  • Only a quarter of BC managers
    had a dedicated budget
       Confidential
Hourly Cost of Downtime


                  Event                            Per Hour
Brokerage House / Large e-commerce site           $6,400,000
Credit Card Sales & Authorization                 $2,600,000
Catalog Sales                                       $90,000
Package Shipping & Transportation                   $28,000
UNIX Networks                                       $75,000
PC LAN                                              $18,000
                                           Source: Quantum Corporation




                            Confidential
Some questions about TIME…

• Consider how each of your critical services could continue
  during a prolonged power loss. …now think about a loss of
  power lasting for 24 hours…
• Which of your critical
  services would be
  jeopardised if your building
  was evacuated for a week
  with all access denied?
• Which services would be
  affected if access were
  denied for a whole month?

                            Confidential
Some questions about DEPENDENCIES…

    How many staff would be                 Do you have an alternative
  needed to continue to cover             building or premises in which to
critical tasks and how would you         work effectively? Is this sufficient?
       accommodate them?                    Can staff work from home?




  Do you need access to any                       Do you have sufficient back-
services not currently available                    up for your data, both
    at your temporary site?                          electronic and paper?

                                   Confidential
Webinar Focus

•   Continuity Statistics
•   Learning From Japan
•   Methodologies
•   Easy2comply New Techniques




                        Confidential
Japan Aftermath

• Multinationals to assume business will be severely
  disrupted
• Supply chain disruption linked to infrastructure,
  energy, utilities and transportation
• Despite history, many companies manage supply
  chain risk ineffectively
• Need understanding of markets
  they sell to, suppliers they rely on,
  and critical dependencies
• Effective planning can sometimes
  make all the difference whether a
  company survives or not
                        Confidential
Disaster Recovery Failures




          Confidential
Top BCM Challenges



• Lack of resources
• Difficult to gain senior management support
• Obtaining wider buy-in from across company




                     Confidential
Webinar Focus

•   Continuity Statistics
•   Learning From Japan
•   Methodologies
•   Easy2comply New Techniques




                        Confidential
What is BCM?


“Business Continuity Management is a business
  owned and driven activity that can provide the
strategic and operational framework to review the
 way your organisation provides its products and
 services and increase its resilience to disruption,
               interruption or loss.”

          Business Continuity Institute



                       Confidential
What is BCM?

• Business Continuity Management is a
  management process…
• … that identifies potential impacts that threaten
  an organisation…
• … and provides a framework for building
  resilience…
• … and the capability for an effective response …
• … which safeguards the interests of its …
• … key stakeholders, reputation, brand and value
  creating activities.
                        Confidential
Who is BCM relevant to?

       • Any organisation, large or
         small, from any sector
       • High risk environments:
         finance / telcos / transport /
         public sector
       • Where need to continue
         operating is essential, for
         organisation, customers and
         stakeholders


         Confidential
Why is BCM important?

• Business will increase its recovery capabilities
  dramatically
• Make the right decisions quickly, cut downtime and
  minimise financial losses
• Being prepared is key as it gives confidence
• Demonstrates duty of care to
  customers and suppliers
• Helps safeguard company
  reputation

                       Confidential
Business Continuity Levels



• RTO      Recovery Time Objective
• MTPoD Maximum Tolerable Period of
  Disruption


            MTPoD > RTO



                    Confidential
Definitions



• RTO: Maximum amount of time that a system
  resource can remain unavailable before there
  is an unacceptable impact on other resources
  or functions

• MTPoD: Total amount of time managers are
  willing to accept for a mission/business
  process outage or disruption

                     Confidential
BC Levels (Example)

BC Level          RTO            MTPoD


   1            48 hours         5 Days


   2            24 hours         4 Days


   3            8 hours          3 Days


   4            4 hours          2 Days


   5            2 hours          1 Day



                  Confidential
Working as Total                   Recovered                  Recovered
                      Normal    Failure               Minimum Level               Normal Level



                    100                                                                             Desired Process
                                                                                                         Level
                    90

                    80
Process Level (%)




                    70
                                  Desired time
                    60              target to                 Maximum
                                                           acceptable time
                                     achieve
                    50                                     below minimum
                                    minimum
                                                                level
                                  process level                                                       Acceptable
                    40
                                                                                                   Minimum Process
                    30                                             MTPoD                                Level
                    20
                                           RTO




                    10

                     0


                          0   2   4   6   8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 42 44 46 48

                                                        Time Horizon (hrs)
                                                                Confidential
Webinar Focus

•   Continuity Statistics
•   Learning From Japan
•   Methodologies
•   Easy2comply New Techniques




                        Confidential
Business Continuity Methodology
Business Structure and Location
                                    Required Resource Analysis
           Mapping




       Process Mapping                 Scenario Identification




                                   Scenario Impact on Resources
 People Resource Dependency
                                           and Locations




   IT Resource Dependency           Building the BCP Plan (Gantt)




Business Impact Analysis (BIA)
                                          Scenario Testing
          on Process




Define BC Level (RTO / MTPoD)       Testing vs. BCP Comparison


                                        Confidential
Screenshots




   Confidential
Screenshots




   Confidential
Conclusions


• Don’t ignore BCP – things happen that are out
  of our control
• Studies show that preparation does help to
  reduce negative outcomes
• Secure management support – you’ll be lost
  without it
• Ensure BC plans are clear and concise
• Test, test and test again!

                     Confidential
Q&A



Jeremy Kaye, VP GRC Strategy
+44 20 7903 5139
jeremy.kaye@easy2comply.com




     Confidential
Thank You
  Visit our website:
 www.easy2comply.com

Contenu connexe

Tendances

Bush.stewart
Bush.stewartBush.stewart
Bush.stewartNASAPMC
 
Using Six Sigma to Drive Service Desk Improvements
Using Six Sigma to Drive Service Desk ImprovementsUsing Six Sigma to Drive Service Desk Improvements
Using Six Sigma to Drive Service Desk Improvementskirkholmes11
 
Rackley mike
Rackley mikeRackley mike
Rackley mikeNASAPMC
 
Demystifying Outsourcing and Global Services Delivery
Demystifying Outsourcing and Global Services DeliveryDemystifying Outsourcing and Global Services Delivery
Demystifying Outsourcing and Global Services DeliveryDigite Inc
 
Selling lean development
Selling lean developmentSelling lean development
Selling lean developmentwozmir
 
Lean IT strategy, lean measurement and organizational design
Lean IT strategy, lean measurement and organizational designLean IT strategy, lean measurement and organizational design
Lean IT strategy, lean measurement and organizational designOperae Partners
 
"Scoping Lean IT: asking the right questions" by Daniel T Jones
"Scoping Lean IT: asking the right questions" by Daniel T Jones"Scoping Lean IT: asking the right questions" by Daniel T Jones
"Scoping Lean IT: asking the right questions" by Daniel T JonesOperae Partners
 
Discovery for Knowledge Work
Discovery for Knowledge WorkDiscovery for Knowledge Work
Discovery for Knowledge WorkAKAGroup
 
Lessons Learned from the Global Sourcing Decison
Lessons Learned from the Global Sourcing DecisonLessons Learned from the Global Sourcing Decison
Lessons Learned from the Global Sourcing DecisonJohn Meyerson
 
Kaiser Governance Enhancemnts Comm Plan
Kaiser Governance Enhancemnts Comm PlanKaiser Governance Enhancemnts Comm Plan
Kaiser Governance Enhancemnts Comm PlanPambie
 
Universal Outsourcing Solution - Updated
Universal Outsourcing Solution - UpdatedUniversal Outsourcing Solution - Updated
Universal Outsourcing Solution - UpdatedRavi Verma
 
TOC in Government: challenges and opportunities. Greg Gardner
TOC in Government: challenges and opportunities. Greg GardnerTOC in Government: challenges and opportunities. Greg Gardner
TOC in Government: challenges and opportunities. Greg GardnercommonsenseLT
 
WhiteHedge Technologies Services Overview
WhiteHedge Technologies Services OverviewWhiteHedge Technologies Services Overview
WhiteHedge Technologies Services OverviewWhiteHedge Technologies
 
Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...
Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...
Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...Practice Paradox
 
Lean practitioner transactional_pune
Lean practitioner transactional_puneLean practitioner transactional_pune
Lean practitioner transactional_puneLeanIndiaConsulting
 
Agile Estimating and Planning
Agile Estimating and PlanningAgile Estimating and Planning
Agile Estimating and PlanningDerek Neighbors
 
David Bottomley, Head of IT Delivery at Specsavers - Promises, promises
David Bottomley, Head of IT Delivery at Specsavers - Promises, promisesDavid Bottomley, Head of IT Delivery at Specsavers - Promises, promises
David Bottomley, Head of IT Delivery at Specsavers - Promises, promisesGlobal Business Events
 

Tendances (18)

Bush.stewart
Bush.stewartBush.stewart
Bush.stewart
 
Using Six Sigma to Drive Service Desk Improvements
Using Six Sigma to Drive Service Desk ImprovementsUsing Six Sigma to Drive Service Desk Improvements
Using Six Sigma to Drive Service Desk Improvements
 
Rackley mike
Rackley mikeRackley mike
Rackley mike
 
Demystifying Outsourcing and Global Services Delivery
Demystifying Outsourcing and Global Services DeliveryDemystifying Outsourcing and Global Services Delivery
Demystifying Outsourcing and Global Services Delivery
 
Selling lean development
Selling lean developmentSelling lean development
Selling lean development
 
Lean IT strategy, lean measurement and organizational design
Lean IT strategy, lean measurement and organizational designLean IT strategy, lean measurement and organizational design
Lean IT strategy, lean measurement and organizational design
 
"Scoping Lean IT: asking the right questions" by Daniel T Jones
"Scoping Lean IT: asking the right questions" by Daniel T Jones"Scoping Lean IT: asking the right questions" by Daniel T Jones
"Scoping Lean IT: asking the right questions" by Daniel T Jones
 
Discovery for Knowledge Work
Discovery for Knowledge WorkDiscovery for Knowledge Work
Discovery for Knowledge Work
 
Lessons Learned from the Global Sourcing Decison
Lessons Learned from the Global Sourcing DecisonLessons Learned from the Global Sourcing Decison
Lessons Learned from the Global Sourcing Decison
 
Kaiser Governance Enhancemnts Comm Plan
Kaiser Governance Enhancemnts Comm PlanKaiser Governance Enhancemnts Comm Plan
Kaiser Governance Enhancemnts Comm Plan
 
Universal Outsourcing Solution - Updated
Universal Outsourcing Solution - UpdatedUniversal Outsourcing Solution - Updated
Universal Outsourcing Solution - Updated
 
TOC in Government: challenges and opportunities. Greg Gardner
TOC in Government: challenges and opportunities. Greg GardnerTOC in Government: challenges and opportunities. Greg Gardner
TOC in Government: challenges and opportunities. Greg Gardner
 
WhiteHedge Technologies Services Overview
WhiteHedge Technologies Services OverviewWhiteHedge Technologies Services Overview
WhiteHedge Technologies Services Overview
 
Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...
Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...
Marketing, Sales Process and Selling Skills for Accounting Firms – Marketing ...
 
Lean practitioner transactional_pune
Lean practitioner transactional_puneLean practitioner transactional_pune
Lean practitioner transactional_pune
 
Agile Estimating and Planning
Agile Estimating and PlanningAgile Estimating and Planning
Agile Estimating and Planning
 
Fusion2012 DRDC case study
Fusion2012 DRDC case studyFusion2012 DRDC case study
Fusion2012 DRDC case study
 
David Bottomley, Head of IT Delivery at Specsavers - Promises, promises
David Bottomley, Head of IT Delivery at Specsavers - Promises, promisesDavid Bottomley, Head of IT Delivery at Specsavers - Promises, promises
David Bottomley, Head of IT Delivery at Specsavers - Promises, promises
 

Similaire à Webinar - Disaster in Japan: A Lesson in BCM

MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017
MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017
MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017Andrew Miller
 
In the Midst of Crisis: Why CFOs are Demanding Active Liquidity Management
In the Midst of Crisis: Why CFOs are Demanding Active Liquidity ManagementIn the Midst of Crisis: Why CFOs are Demanding Active Liquidity Management
In the Midst of Crisis: Why CFOs are Demanding Active Liquidity ManagementKyriba Corporation
 
Chattanooga sme oee down time presentation
Chattanooga sme oee down time presentationChattanooga sme oee down time presentation
Chattanooga sme oee down time presentationJames Mansfield
 
Capgemini: Observability within the Dutch government
Capgemini: Observability within the Dutch governmentCapgemini: Observability within the Dutch government
Capgemini: Observability within the Dutch governmentElasticsearch
 
Ca Additional Research Charts
Ca Additional Research ChartsCa Additional Research Charts
Ca Additional Research ChartsCA RMDM Latam
 
Manufacturing and Service Technologies
Manufacturing and Service TechnologiesManufacturing and Service Technologies
Manufacturing and Service Technologiessamer dofash
 
Production-Ready Kubernetes: It's Not About Technology
Production-Ready Kubernetes: It's Not About TechnologyProduction-Ready Kubernetes: It's Not About Technology
Production-Ready Kubernetes: It's Not About TechnologyAntoine Craske
 
The Impact of Cloud on Procurement Presentation 30th may 2012
The Impact of Cloud on Procurement Presentation 30th may 2012The Impact of Cloud on Procurement Presentation 30th may 2012
The Impact of Cloud on Procurement Presentation 30th may 2012Coupa Software
 
Managing a Major Incident
Managing a Major IncidentManaging a Major Incident
Managing a Major IncidentNUS-ISS
 
Business process reengineering
Business process reengineeringBusiness process reengineering
Business process reengineeringnavi2488
 
VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud VMworld
 
Agility And The Way To SOA
Agility And The Way To SOAAgility And The Way To SOA
Agility And The Way To SOAFrank Müller
 
70% Improvement in Service and Product Delivery on Implementing DevOps
70% Improvement in Service and Product Delivery on Implementing DevOps70% Improvement in Service and Product Delivery on Implementing DevOps
70% Improvement in Service and Product Delivery on Implementing DevOpsCygnet Infotech
 
Organize and Justify Your EMI Initiative
Organize and Justify Your EMI InitiativeOrganize and Justify Your EMI Initiative
Organize and Justify Your EMI InitiativeNorthwest Analytics
 
High Tech Manufacturing
High Tech ManufacturingHigh Tech Manufacturing
High Tech ManufacturingGarima Sinha
 
Cheapest User Stories - The Achilles Heel of Agile
Cheapest User Stories - The Achilles Heel of Agile Cheapest User Stories - The Achilles Heel of Agile
Cheapest User Stories - The Achilles Heel of Agile Anton Oosthuizen
 

Similaire à Webinar - Disaster in Japan: A Lesson in BCM (20)

Why Managed Services
Why Managed ServicesWhy Managed Services
Why Managed Services
 
Santosh Kumbar
Santosh KumbarSantosh Kumbar
Santosh Kumbar
 
MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017
MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017
MGT3342BUS - Architecting Data Protection with Rubrik - VMworld 2017
 
In the Midst of Crisis: Why CFOs are Demanding Active Liquidity Management
In the Midst of Crisis: Why CFOs are Demanding Active Liquidity ManagementIn the Midst of Crisis: Why CFOs are Demanding Active Liquidity Management
In the Midst of Crisis: Why CFOs are Demanding Active Liquidity Management
 
Group b opm-ppt_final
Group b opm-ppt_finalGroup b opm-ppt_final
Group b opm-ppt_final
 
Chattanooga sme oee down time presentation
Chattanooga sme oee down time presentationChattanooga sme oee down time presentation
Chattanooga sme oee down time presentation
 
Capgemini: Observability within the Dutch government
Capgemini: Observability within the Dutch governmentCapgemini: Observability within the Dutch government
Capgemini: Observability within the Dutch government
 
Ca Additional Research Charts
Ca Additional Research ChartsCa Additional Research Charts
Ca Additional Research Charts
 
Manufacturing and Service Technologies
Manufacturing and Service TechnologiesManufacturing and Service Technologies
Manufacturing and Service Technologies
 
Production-Ready Kubernetes: It's Not About Technology
Production-Ready Kubernetes: It's Not About TechnologyProduction-Ready Kubernetes: It's Not About Technology
Production-Ready Kubernetes: It's Not About Technology
 
The Impact of Cloud on Procurement Presentation 30th may 2012
The Impact of Cloud on Procurement Presentation 30th may 2012The Impact of Cloud on Procurement Presentation 30th may 2012
The Impact of Cloud on Procurement Presentation 30th may 2012
 
Managing a Major Incident
Managing a Major IncidentManaging a Major Incident
Managing a Major Incident
 
Business process reengineering
Business process reengineeringBusiness process reengineering
Business process reengineering
 
VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud
 
Agility And The Way To SOA
Agility And The Way To SOAAgility And The Way To SOA
Agility And The Way To SOA
 
70% Improvement in Service and Product Delivery on Implementing DevOps
70% Improvement in Service and Product Delivery on Implementing DevOps70% Improvement in Service and Product Delivery on Implementing DevOps
70% Improvement in Service and Product Delivery on Implementing DevOps
 
Accelerate Time to Business Outcomes through BPM
Accelerate Time to Business Outcomes through BPMAccelerate Time to Business Outcomes through BPM
Accelerate Time to Business Outcomes through BPM
 
Organize and Justify Your EMI Initiative
Organize and Justify Your EMI InitiativeOrganize and Justify Your EMI Initiative
Organize and Justify Your EMI Initiative
 
High Tech Manufacturing
High Tech ManufacturingHigh Tech Manufacturing
High Tech Manufacturing
 
Cheapest User Stories - The Achilles Heel of Agile
Cheapest User Stories - The Achilles Heel of Agile Cheapest User Stories - The Achilles Heel of Agile
Cheapest User Stories - The Achilles Heel of Agile
 

Plus de easy2comply

easy2comply Partner's Training Workbook
easy2comply Partner's Training Workbookeasy2comply Partner's Training Workbook
easy2comply Partner's Training Workbookeasy2comply
 
Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act
Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act
Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act easy2comply
 
Webinar - Risk Methodologies - Why are there so many?
Webinar - Risk Methodologies - Why are there so many?Webinar - Risk Methodologies - Why are there so many?
Webinar - Risk Methodologies - Why are there so many?easy2comply
 
Online Training Solvency II
Online Training Solvency IIOnline Training Solvency II
Online Training Solvency IIeasy2comply
 
Online Training Sarbanes-Oxley
Online Training Sarbanes-OxleyOnline Training Sarbanes-Oxley
Online Training Sarbanes-Oxleyeasy2comply
 
Online Training Internal Control Management
Online Training Internal Control ManagementOnline Training Internal Control Management
Online Training Internal Control Managementeasy2comply
 
Online Training Information Security Management
Online Training Information Security ManagementOnline Training Information Security Management
Online Training Information Security Managementeasy2comply
 
Online Training Basel II
Online Training Basel IIOnline Training Basel II
Online Training Basel IIeasy2comply
 
Compliance Management Software
Compliance Management SoftwareCompliance Management Software
Compliance Management Softwareeasy2comply
 
Risk Management Software
Risk Management SoftwareRisk Management Software
Risk Management Softwareeasy2comply
 

Plus de easy2comply (10)

easy2comply Partner's Training Workbook
easy2comply Partner's Training Workbookeasy2comply Partner's Training Workbook
easy2comply Partner's Training Workbook
 
Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act
Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act
Foreign Corrupt Practices Act of 1977 UK Anti-Bribery Act
 
Webinar - Risk Methodologies - Why are there so many?
Webinar - Risk Methodologies - Why are there so many?Webinar - Risk Methodologies - Why are there so many?
Webinar - Risk Methodologies - Why are there so many?
 
Online Training Solvency II
Online Training Solvency IIOnline Training Solvency II
Online Training Solvency II
 
Online Training Sarbanes-Oxley
Online Training Sarbanes-OxleyOnline Training Sarbanes-Oxley
Online Training Sarbanes-Oxley
 
Online Training Internal Control Management
Online Training Internal Control ManagementOnline Training Internal Control Management
Online Training Internal Control Management
 
Online Training Information Security Management
Online Training Information Security ManagementOnline Training Information Security Management
Online Training Information Security Management
 
Online Training Basel II
Online Training Basel IIOnline Training Basel II
Online Training Basel II
 
Compliance Management Software
Compliance Management SoftwareCompliance Management Software
Compliance Management Software
 
Risk Management Software
Risk Management SoftwareRisk Management Software
Risk Management Software
 

Webinar - Disaster in Japan: A Lesson in BCM

  • 2. Presenter Jeremy Kaye, VP GRC Strategy +44 20 7903 5139 jeremy.kaye@easy2comply.com Confidential
  • 3. Housekeeping • The slides for this event will be distributed afterwards • The webinar recording will be archived on easy2comply website • Answer all the polls • Q & A at the end Confidential
  • 4. Dedication We dedicate this webinar to all those that lost their life in the Japan earthquake, those that were injured, and to those that survived Our thoughts and wishes are with the Japanese people Confidential
  • 5. What is easy2comply? easy2comply is a functionally-rich software solution, that enable companies to effectively manage multiple GRC processes on a single platform Confidential
  • 6. Webinar Focus • Continuity Statistics • Learning From Japan • Methodologies • Easy2comply New Techniques Confidential
  • 7. Statistics…. • 43% of companies experiencing disasters never re-open, and 29% close within two years (McGladrey and Pullen) • A company that experiences a computer outage lasting more than 10 days will never fully recover financially (DRP – Jon Toigo) • 88% of e-commerce is not covered by a DR / BC plan (HP) • 42% of managers do not believe their plans would be effective (HP) Confidential
  • 8. ….and more statistics • 50% of UK businesses do not have a BC plan • 79% of those that had plans and were forced to use them found a significant reduction in the impact • Fewer than half that had plans actually tested them • Only a quarter of BC managers had a dedicated budget Confidential
  • 9. Hourly Cost of Downtime Event Per Hour Brokerage House / Large e-commerce site $6,400,000 Credit Card Sales & Authorization $2,600,000 Catalog Sales $90,000 Package Shipping & Transportation $28,000 UNIX Networks $75,000 PC LAN $18,000 Source: Quantum Corporation Confidential
  • 10. Some questions about TIME… • Consider how each of your critical services could continue during a prolonged power loss. …now think about a loss of power lasting for 24 hours… • Which of your critical services would be jeopardised if your building was evacuated for a week with all access denied? • Which services would be affected if access were denied for a whole month? Confidential
  • 11. Some questions about DEPENDENCIES… How many staff would be Do you have an alternative needed to continue to cover building or premises in which to critical tasks and how would you work effectively? Is this sufficient? accommodate them? Can staff work from home? Do you need access to any Do you have sufficient back- services not currently available up for your data, both at your temporary site? electronic and paper? Confidential
  • 12. Webinar Focus • Continuity Statistics • Learning From Japan • Methodologies • Easy2comply New Techniques Confidential
  • 13. Japan Aftermath • Multinationals to assume business will be severely disrupted • Supply chain disruption linked to infrastructure, energy, utilities and transportation • Despite history, many companies manage supply chain risk ineffectively • Need understanding of markets they sell to, suppliers they rely on, and critical dependencies • Effective planning can sometimes make all the difference whether a company survives or not Confidential
  • 15. Top BCM Challenges • Lack of resources • Difficult to gain senior management support • Obtaining wider buy-in from across company Confidential
  • 16. Webinar Focus • Continuity Statistics • Learning From Japan • Methodologies • Easy2comply New Techniques Confidential
  • 17. What is BCM? “Business Continuity Management is a business owned and driven activity that can provide the strategic and operational framework to review the way your organisation provides its products and services and increase its resilience to disruption, interruption or loss.” Business Continuity Institute Confidential
  • 18. What is BCM? • Business Continuity Management is a management process… • … that identifies potential impacts that threaten an organisation… • … and provides a framework for building resilience… • … and the capability for an effective response … • … which safeguards the interests of its … • … key stakeholders, reputation, brand and value creating activities. Confidential
  • 19. Who is BCM relevant to? • Any organisation, large or small, from any sector • High risk environments: finance / telcos / transport / public sector • Where need to continue operating is essential, for organisation, customers and stakeholders Confidential
  • 20. Why is BCM important? • Business will increase its recovery capabilities dramatically • Make the right decisions quickly, cut downtime and minimise financial losses • Being prepared is key as it gives confidence • Demonstrates duty of care to customers and suppliers • Helps safeguard company reputation Confidential
  • 21. Business Continuity Levels • RTO Recovery Time Objective • MTPoD Maximum Tolerable Period of Disruption MTPoD > RTO Confidential
  • 22. Definitions • RTO: Maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other resources or functions • MTPoD: Total amount of time managers are willing to accept for a mission/business process outage or disruption Confidential
  • 23. BC Levels (Example) BC Level RTO MTPoD 1 48 hours 5 Days 2 24 hours 4 Days 3 8 hours 3 Days 4 4 hours 2 Days 5 2 hours 1 Day Confidential
  • 24. Working as Total Recovered Recovered Normal Failure Minimum Level Normal Level 100 Desired Process Level 90 80 Process Level (%) 70 Desired time 60 target to Maximum acceptable time achieve 50 below minimum minimum level process level Acceptable 40 Minimum Process 30 MTPoD Level 20 RTO 10 0 0 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 42 44 46 48 Time Horizon (hrs) Confidential
  • 25. Webinar Focus • Continuity Statistics • Learning From Japan • Methodologies • Easy2comply New Techniques Confidential
  • 26. Business Continuity Methodology Business Structure and Location Required Resource Analysis Mapping Process Mapping Scenario Identification Scenario Impact on Resources People Resource Dependency and Locations IT Resource Dependency Building the BCP Plan (Gantt) Business Impact Analysis (BIA) Scenario Testing on Process Define BC Level (RTO / MTPoD) Testing vs. BCP Comparison Confidential
  • 27. Screenshots Confidential
  • 28. Screenshots Confidential
  • 29. Conclusions • Don’t ignore BCP – things happen that are out of our control • Studies show that preparation does help to reduce negative outcomes • Secure management support – you’ll be lost without it • Ensure BC plans are clear and concise • Test, test and test again! Confidential
  • 30. Q&A Jeremy Kaye, VP GRC Strategy +44 20 7903 5139 jeremy.kaye@easy2comply.com Confidential
  • 31. Thank You Visit our website: www.easy2comply.com